CVE-2026-16498
CVSS 10 CRITICAL: the terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
Vulnerabilità ed exploit
Il problema non è un bug qualsiasi. Qui si rompe il confine di fiducia dentro le superfici di amministrazione: un token può finire nella richiesta di un altro tenant, un agent gestito può essere impersonato, un modello GeoDjango visibile allo staff può diventare scrittura su disco e, su alcune configurazioni, code execution.
HashiCorp, Veeam e Django hanno corretto 11 vulnerabilità tra Terraform MCP Server, Veeam Service Provider Console e Django. Le più gravi sono CVE-2026-16498, con riuso cross-tenant del token in Terraform MCP, una falla in Veeam che espone le credenziali di un managed agent, e CVE-2026-15307 in GeoDjango; i fix disponibili sono Terraform MCP Server 1.1.0 o successivo, Veeam Service Provider Console 9.3.0.35057 e Django 6.0.8 o 5.2.17.
Il rischio resta concentrato in configurazioni precise: streamable-HTTP per Terraform MCP, build Veeam 9 precedenti a 9.3, e view permission su modelli GeoDjango con campi spaziali. In questi casi, patchare chiude la falla, ma non annulla il raggio d’azione se un token o le credenziali di un agent sono già stati riusati o esposti.
2 fonti · 5 ago
CVSS 10 CRITICAL: the terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
CVSS 8.8 HIGH: an issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically…
NCSC-NL Advisories
Kwetsbaarheden verholpen in Veeam Service Provider Console
Veeam heeft meerdere kwetsbaarheden verholpen in Veeam Service Provider Console.
originaleThe Hacker News
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and Django patch 11 flaws, including cross-tenant token reuse, agent credential exposure, and possible code execution.
originalePart of the PlainSec briefing for 2026-08-06
Every edition of this story: La fiducia tra tenant, agent e staff si rompe nelle console di gestione